- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Remote Access - SSH to Gateway
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Remote Access - SSH to Gateway
Hi,
I can't SSH to the firewall the I connect to via remote access VPN. Firewall rules are in place for SSH and webUI access to the firewall. I know in other VPN communities there is a tab for "excluded services". Is there a similar option for remote access VPN community?
I can get to the webUI but I can't SSH. Logs show traffic being decrypted.
I am running R81.10 mgmt and R80.40 firewall.
Thank you.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Rock and Genesis for your help. I found the issue. My SSH session was saved with the external IP, and I did not realize until now. 😅
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you see any logs for port 22 when trying?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yup
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What do they show? Did you try zdebug on command line?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hmm I don't see logs anymore but I did enable split tunneling and manually specified the encryption domain.
I do have a firewall rule that should allow this traffic...
Src: office mode network
Dst: FW
Services: SSH and webUI port
I am able to access the webUI and I see accept and decrypt logs for this traffic from my office mode IP to the internal IP of the firewall.
When I try to SSH I don't see logs. I do see drops in the zdebug. It shows this connection being dropped but the weird thing is the source is my external IP trying to hit destination of the external IP of the firewall.
Shouldn't this traffic be hitting the same rule that allows webUI access?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Message me directly, I have time to do remote, I have a feeling its something simple you might be missing.
Cheers!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Silly question have you updated the allowed list in GAIA?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Rock and Genesis for your help. I found the issue. My SSH session was saved with the external IP, and I did not realize until now. 😅
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, sometimes smallest things pose a problem. Glad it works now : - )
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Its a good reminder to us all, check the basics first!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree with you wholeheartedly!
